Sun describes a flaw at: http://sunsolve.sun.com/search/document.do?assetkey=1-26-103073-1 Three vulnerabilities in Java Web Start may allow an untrusted application to determine the location of the Java Web Start cache.
The list of fixed products with their respective errata is here: https://access.redhat.com/security/cve/CVE-2007-5238